CVE-2026-87165
Oracle E-Business Suite vulnerability analysis and mitigation

Overview

CVE-2026-87165 is a high-severity vulnerability in the Oracle Contract Lifecycle Management for Public Sector product, specifically within the ECC For Award and IDV component of Oracle E-Business Suite. The affected version is V16. Disclosed on September 15, 2026, as part of Oracle's Critical Security Patch Update (CSPU), the vulnerability allows a low-privileged attacker with network access via HTTP to fully compromise the affected application. It carries a CVSS v3.1 base score of 8.8 (High) (Oracle Advisory).

Technical details

The vulnerability is classified as an easily exploitable flaw (no specific CWE has been publicly disclosed) that can be triggered by a low-privileged, authenticated attacker over HTTP without requiring user interaction. The attack vector is network-based with low attack complexity, meaning no special conditions or race conditions are required for exploitation. Oracle's advisory characterizes the potential outcome as a full takeover of the Oracle Contract Lifecycle Management for Public Sector application, consistent with remote code execution behavior. No public technical write-ups or proof-of-concept code have been identified at this time (Oracle Advisory).

Impact

Successful exploitation results in complete compromise of the Oracle Contract Lifecycle Management for Public Sector application, with high impact to confidentiality, integrity, and availability. An attacker could read sensitive procurement and contract data, modify system configurations or application data, and disrupt service availability. Given the public-sector context of the affected product, exploitation could expose sensitive government contracting information and potentially enable lateral movement within connected Oracle E-Business Suite environments (Oracle Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability has an EPSS score of approximately 0.0035 (0.35%), indicating a currently low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection support is available via Qualys scanner (detection ID: 20626) (Oracle Advisory).

Mitigation and workarounds

Oracle has released a security patch for this vulnerability as part of the September 2026 Critical Security Patch Update, published on September 15, 2026. Organizations running Oracle Contract Lifecycle Management for Public Sector V16 should apply the patch immediately via the Oracle E-Business Suite patch availability documentation. As a temporary measure, Oracle recommends restricting network access to the affected component via HTTP to only authorized users and networks, though this should not be considered a long-term solution. Oracle strongly advises against skipping security patch updates (Oracle Advisory).

Community reactions

Oracle's advisory notes that the company continues to receive reports of attackers exploiting vulnerabilities for which patches have already been released, and strongly urges customers to apply patches without delay. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-87165 has been identified beyond the standard advisory coverage (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle E-Business Suite vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-87165HIGH8.8
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoSep 15, 2026
CVE-2026-70813HIGH8.8
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoAug 18, 2026
CVE-2026-70812HIGH8.8
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoAug 18, 2026
CVE-2026-70814HIGH8.1
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoAug 18, 2026
CVE-2026-70837HIGH7.1
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management